Hackers Use Domain Shadowing. Domain Shadowing is a Subcategory of DNS Hijacking. Cyber Security.

preview_player
Показать описание
Hackers Use Domain Shadowing. Domain Shadowing is a Subcategory of DNS Hijacking. Cyber Security. Threat analysts at Palo Alto Networks (Unit 42) discovered that the phenomenon of 'domain shadowing' might be more prevalent than previously thought, uncovering 12,197 cases while scanning the web between April and June 2022.

Domain shadowing is a subcategory of DNS hijacking, where threat actors compromise the DNS of a legitimate domain to host their own subdomains for use in malicious activity but do not modify the legitimate DNS entries that already exist. In the meantime, the threat actors are free to host C2 (command and control) addresses, phishing sites, and malware-dropping points, abusing the good reputation of the hijacked domain to bypass security checks. The attackers can theoretically change the DNS records to target users and owners of the compromised domains, but they typically prefer to take the stealthy path described above.

Hard to detect
Unit 42 explains that detecting real cases of domain shadowing is particularly challenging, which makes the tactic so alluring for the perpetrators.

The analysts mention that VirusTotal marked only 200 domains as malicious out of the 12,197 domains Palo Alto's detectors uncovered.
Рекомендации по теме
Комментарии
Автор

Always keeping us up on game!
Thanks, PBO👍🏾

sparksays
Автор

Pretty interesting stuff. Learn something new everyday.

xavieredwards
Автор

Aye... sub domain is the part before the domain not the part after. Example hr(.)company(.)domain instead of company(.)domain/hr

CalvinHenderson
Автор

Sir, your voice is too low, hard to listen properly.

parastalreja